October 2019

327 tweets

Replying to @null and @SimonDeDeo

Not sure what wall you’re hitting up against, but I’ve found that people react quite strongly to *dark* patterns — the negative language might catch attention better? Eg. of a source: webtransparency.cs.princeton.edu/dark-patterns/

Replying to @null and @SimonDeDeo

Right, though to be honest I never quite understood why people found Alexander to be all that interesting. I suspect showing dark pattern languages may be working better because people have much pent-up anger about them :)

Replying to @null and @SimonDeDeo, @mcmansionhell

Great example :) Have you tried a dissection of McMansions?

Replying to @null and @SimonDeDeo

For McMansions there is always the risk that they will have bad taste — but I think everyone is annoyed by bad UI? If you’re cruel you could get them to dissect the antipattern language in userinyerface.com.

Replying to @null and @SimonDeDeo, @mcmansionhell

This was also a great presentation from @liorjs but I don’t know how well it was recorded: youtube.com/watch?v=Ng1Vrd…

Replying to @gordonbrander

To be eaten with standard tea en.wikipedia.org/wiki/ISO_3103
What would make this an even better feature would be if @Android reported on its own background data collection, not just those of non-Google apps. 🤭 digitalcontentnext.org/blog/2018/08/2…
Quoting a tweet by @lizthegrey ↗
↺ 4

Replying to @cwarzel

Replying to @cwarzel

It’s clearly written and well documented, and it answers *exactly* your question. @DinaSrinivasan wrote a good summary for the site (nytimes.com/2019/05/28/opi…) but given your interests I’d recommend the full thing!

Replying to @mblafkin and @Android

Absolutely. That Android is a privacy train wreck is not surprising but the anticompetitive angle is one people are likely to miss.

Replying to @mblafkin and @Android

It is a nice feature — I can think of ways of making this less reactive but purely for privacy it’s a good step. I agree with your analysis, it’s hard to parse Google’s strategy there. I wonder if they may simply not realise what everyone on the outside is seeing?

Replying to @mblafkin and @Android

Yes! And from the inside self-preferencing probably just feels like using your own stuff and trusting your co-workers, neither of which is morally problematic at the local scale.

Replying to @F_Kaltheuner and @Android

I haven't found someone who's seen that dialog for anything Google yet, I've been asking around. The thing is, I don't think any Google app does background collection, I suspect they simply rely on OS/Play services doing that for them!

Thread of 2 tweets

Replying to @matthfew and @AlecStapp

Hahaha 😂

Replying to @matthfew and @mercatus

Same for @LawEconCenter, they're not even trying to make it look honest, it's just generating references with the right titles so lobbyists have "research" to cite that staffers and reporters too often won't check.

Replying to @taravancil

If you need a car it's not a city.

Replying to @ericlaw

So, this is a neat and well thought out little improvement and the security plus is real, but I'm still not seeing how it helps privacy? Having the wrong default and forcing others to regularly delete their cookies helps privacy not one bit.
I've been wondering if a similar approach could be used to indicate data rights over the cookie, allowing processors and blocking controllers by default. It's what best matches a distinction between legitimate third parties and others.

Thread of 2 tweets

Replying to @can and @femalegazebot

You two can never be over, what would I come to this site for if you were?

Replying to @jason_kint

Yes, the "conspiracy theory" post. Inspired!

Replying to @drogersuk and @torgo, @marcosc

I feel like this has been said before...

Replying to @tobie and @brucel, @marcosc

It's not pure monetisation, the ability eg. to implement a metered paywall that private mode doesn't defeat can help, too (and not just publishers).

Replying to @msdixon and @taravancil

I don’t see it as being about transport, though. In NYC if you yanked out transportation I wouldn’t be able to work where I do but apart from that I could do everything, even go to the movies. Without that do you have the dynamics of a city?

Replying to @msdixon and @taravancil

I feel like places like LA or Houston are more like a bunch of cities glommed together by continuous periurban areas. A colony more than an organism?

Replying to @msdixon and @taravancil

You opinion isn’t any less valid than mine! I grew up in the perisuburb of a provincial shithole — you could walk, but there was nothing to walk to :)

Replying to @null and @benlikestocode, @msdixon, @taravancil

That’s exactly Paris :)

Replying to @msdixon and @taravancil

I think we’re in mean agreement here. One thing it took me a while to parse out is that Paris’s supposedly outstanding public transportation is only good in the tiny rich intra-muros area. NYC’s, which is broken in many ways, is far more egalitarian.

Replying to @msdixon and @taravancil

And, importantly, there is a feedback loop at play: infrastructure causes affluence.
Excellent thread on the thorny problems of DoH.
Quoting a tweet by @C___CS ↗

Replying to @Kent_Walker and @Google

Is that the right link?
These are legitimate concerns, but I wonder if Microsoft might not be testing a broader “Google products, but with privacy” as Edge seems to be doing with Chrome. It would be interesting to watch. (And hey, the phone looks pretty cool.)
Quoting a tweet by @danielahanley ↗
I very much second Jake. If you tried Inkscape a while back and were put off by how “Linux on the Desktop” the experience felt, I recommend you try again. Now all I need is an actual sense of artistry.
Quoting a tweet by @jaffathecake ↗
↺ 1
This is, like, the tagline for my soul.
Quoting a tweet by @JoeBeOne ↗

Replying to @JoeBeOne

Yeah, don't go there, man. Bad things happen over there.

Replying to @oliviasolon and @jason_kint

The first one means you've been put in a lookalike segment based on the tracking that Facebook does on Hatch's site. They probably don't know why you're similar, it's likely an opaque ML system of some kind. (I'm not saying that's, just trying to add context.)

Replying to @oliviasolon and @jason_kint

Yeah, I'm pretty sure explainability was never on the whiteboard for this one 🙂
AnitaB.org recognised the @nytimes as "Top Company for Women Technologists"! 🎉 Periodic reminder that we have a whole bunch of open positions at a growing, friendly, ethical company: nytimes.wd5.myworkdayjobs.com/en-US/NYT/
Quoting a tweet by @AnitaB_org ↗
This AdWeek article is both fear-mongering and interesting. No, 87% of people are not going to opt out of behavioural ads on every site. But 87% of people *want to*. That’s why this should be done at the browser and operating system level. adweek.com/programmatic/8…
↺ 12

Replying to @publictorsten

Honestly, the opt out is designed in such a way in the law that it’s barely dark patterns. You need to have a link to opt out on the page. Even if it’s prominent people won’t bother every time.

Replying to @sidnext2none

They might want ads! They just don’t want their data syphoned off for them.

Replying to @LAM_Barrett

Indeed. I’m pretty sure that ten or even five years ago that number would have been much lower.

Replying to @jyasskin and @nytimes

Ethical doesn’t mean you never screw up.

Replying to @htmlparserbook and @briankardell

Are there plans for a paper book?

Replying to @zcorpan and @htmlparserbook, @briankardell

Sweet, I look forward to it! It’s a really cool topic.

Replying to @null and @avadacatavra, @marcosc

Funny that’s how I read it too :)

Replying to @null and @koalie, @nytimes

A lot of positions are remote-friendly, thought it’s not always indicated clearly. The remote positions would probably report to NYC.

Replying to @trekonomics

I’m Robert, so

Replying to @tobie

I do, but consensually.

Replying to @samoore_

I don't disagree with the sentiment, they are operating on a pretty high budget relative to the complexity of the service they provide. It only looks like success because the rest of the field is insanely bad.
Does anyone know if the @sciathome games removed "temporarily for GDPR compliance" are ever coming back? scienceathome.org/games/quantum-…

Replying to @ElliotLepers and @joelgombin

Je n'ai pas exploré, mais j'ai des doutes sur la viabilité de l'idée 🙂

Replying to @sciathome

Wonderful, thanks! I never noticed QM2, brilliant.

Replying to @tabatkins

Was there a decision at TPAC as to where that is all supposed to go for standards discussion?

Replying to @tabatkins

The Sandbox Privacy announcement said that the plan was to pursue all of those pieces in a standards group, but when I asked “which” at the time I was told it would be discussed at TPAC.
I was looking for the AMP Conf site and found this… ampconference.com I was confused for a little while.

Replying to @tabatkins

Maybe the budget makes sense in PING, but some of the other stuff seems more like WebAdv or possibly TAG work?

Replying to @null and @dauwhe

In CDATA's defence that construct there really isn't CDATA's fault.

Replying to @tabatkins

Do you know of any discussion of timelines for what where? I can’t seem to find any info (which doesn’t mean it’s not nicely written in a corner, this is standards). I’m trying to assess whether it would make sense for us to join.
Has anyone figured out if you can use AMP *and* be CCPA compliant? github.com/ampproject/amp…

Replying to @Iwillleavenow

French fries and vanilla milkshake. Red wine and coffee.

Replying to @temptoetiam

Not relatable at all. Nooooooot at all.
Depicting powerful women as needlessly aggressive, Buttigieg-style.
Quoting a tweet by @sahilkapur ↗
↺ 1

Replying to @othermaciej and @tabatkins

I think it should accept them for consideration. Little in there does much to fix the web, and an uncharitable view could be that it seeks to not break Google's self-serving idea of how others should do business on the web, but some of the ideas are okay.

Replying to @johnwilander and @othermaciej, @tabatkins

Did anyone actually say "we're going to ship with a warning"?

Replying to @_abialas and @femalegazebot

Poutine time!

Replying to @jyasskin

Do you have a public pointer to background? Is there a possibility that the second thing doesn't get removed?

Replying to @Chronotope

Why though.

Replying to @jyasskin

Agreed it's not super crisp...

Replying to @blassey and @johnwilander, @othermaciej, @tabatkins

Have you looked into reporting the behaviour into a Safe Browsing db of sorts so as to feed blocklists?

Replying to @null and @SimonDeDeo

There's nothing immoral about bugs 😁

Replying to @C4COMPUTATION and @nybooks, @LRB

You don't even need AI. Large-scale A/B testing and personnalisation opens the door to insuperable nudging, the potential for collective control is quite astounding.
↺ 1
The war between monopoly power and democracy is not new, even if it has become particularly salient. I've been waiting for this book to come out for a while, really looking forward to starting it in a couple of weeks!
Quoting a tweet by @matthewstoller ↗
↺ 2

Replying to @null and @SimonDeDeo

I'm jealous. I've seen advance copies at work but apparently you can't just steal books from Opinion.

Replying to @null and @SimonDeDeo

Careful Simon, the bedbugs bite.

Replying to @null and @marcosc

Wow, you're so young! 🎂❤️🤗💋

Replying to @__apf__

I used to use it but it's quite clunky. I've been wondering about trying it again, I use Twitter for book friends and it's not ideal.

Replying to @__apf__

Yeah, in my case the "sharing my taste" part has become a bit of a limiting factor 😁

Replying to @johnnyryan and @PrivacyMatters, @IABEurope, @TownsendFeehan, @brave

They're not there for the debate, they just care about survival... 🤷‍♂️

Replying to @johnnyryan and @PrivacyMatters, @IABEurope, @TownsendFeehan, @brave

I couldn't agree more, but the IAB hasn't cottoned on to that. Amongst those working on reform so that advertising remains viable I don't think anyone is considering taking ideas to the IAB.

Replying to @mbeisen

I would have it tied with digital advertising. Tough one.

Replying to @Chronotope

The question becomes: can you imagine a year from now?
We often forget, but tech has history: "Introduced in 1972, the Information Bank was an electronic retrieval system that gave subscribers computer access, through telephone lines, to long abstracts of articles from The Times and other newspapers" nytimes.com/2019/10/01/bus…
↺ 2
If you're in New York in early November come join us at @AllTechIsHuman! Just looking at the list of people I'm already worried I might not have time to say hi to everyone whose work I ❤️. alltechishumannyc.splashthat.com
↺ 3

Replying to @null and @benlikestocode

It's on the 9th!

Replying to @johnwilander and @blassey, @othermaciej, @tabatkins

Yes, it's great to explore more privacy stuff, we must absolutely do that, but it would be more helpful to implement proven solutions like ITP before going down any number of potential rabbit holes.

Replying to @tabatkins and @johnwilander, @blassey, @othermaciej

I'm... not sure what you're saying? Which plausible harms? Helping who?

Replying to @Chronotope and @blassey, @johnwilander, @othermaciej, @tabatkins

Well, not even the Disconnect list. The threat model from fingerprinting is mostly the smaller players (there is credible GDPR enforcement so the bigger ones are less tempted). So it’ll probably be Disconnect minus Google and Facebook.
↺ 1

Replying to @Chronotope and @blassey, @johnwilander, @othermaciej, @tabatkins

But you knew that — the Privacy Sandbox fixes every privacy issue you can fix without breaking Google’s Web.

Replying to @johnwilander and @Chronotope, @blassey, @othermaciej, @tabatkins

In general the ability to treat different script sources differently could be very useful for a lot of things. I like that.

Replying to @johnwilander and @jyasskin, @Chronotope, @blassey, @othermaciej, @tabatkins

Yes, flip it around and only grant powers to known sources sounds ideal and in line with the direction of the platform.

Replying to @jyasskin and @johnwilander, @Chronotope, @blassey, @othermaciej, @tabatkins

Have you documented the pitfalls so others can learn from them by any chance?

Replying to @joejerome

Wasn't there some middle ground on the table for the CCPA at some point? Like a PRA but mediated through a degree of filtering?

Replying to @joejerome

I think the suggestion (from Tom Umberg?) was to use Section 17200 for the CCPA, which I believe enables the AG, DAs, county counsels, and city attorneys or something like that. But I’m short on details on account of 1) not being a lawyer and 2) it’s lost in the fog of war.

Replying to @snowjake and @joejerome

My understanding (from dim recollection of discussion with Umberg) was that they tried to push this as a negotiated middle-ground but it wasn’t enough for HBJ and too much for CalChamber and their friends. But I wonder if it might be a mechanism for Joe’s original question!

Replying to @Chronotope and @tabatkins

You're welcome.
Welcome to the present of climate change. sfchronicle.com/california-wil…
↺ 2
"Evolution doesn’t spend millions of dollars lobbying Congress to ensure that its plans go unfettered."
Quoting a tweet by @roseveleth ↗
↺ 2

Thread of 2 tweets

I don’t think the hard skills/soft skills dichotomy is as bad as it’s made out to be. Hard skills: figuring out long-term healthy interactions with complicated entities, eg. people. Soft skills: stuff you can mostly cut-and-paste from StackOverflow.
Quoting a tweet by @mulegirl ↗
↺ 11

Replying to @jason_kint and @fmanjoo, @ceciliakang

This lists some of the issues that would incline me to agree that Facebook hasn’t done the job: blog.mozilla.org/blog/2019/04/2… Also, even if they did it right you could still have opaque uploaded segments and lookalikes — so microtargeting would remain an issue.

Replying to @cepcam and @temptoetiam

Yes.

Replying to @jason_kint

Facebook is known to be a reliable source of reporting for video views :)
What's the gold standard for headless browser testing these days? Anything that integrates well with VPNs?

Replying to @jny and @jason_kint

The authors had an earlier one in January, I'm surprised it didn't get more attention at the time. They seem to be read mostly in Europe but very little is EU-specific.

Replying to @jason_kint and @jny, @adexchanger

Yes, I’m not surprised that *those* people are paying attention, but given the level of angst about Google’s approach to revenue from both advertisers and publishers I’m surprised it isn’t covered more eg. in the trade press.
Quoting a tweet by @kottke ↗

Replying to @tabatkins

That's not much more than for the men's in NYC!
I love the smell of draft regulation in the morning. oag.ca.gov/privacy/ccpa
↺ 1

Replying to @KenjiBaheux

I'm not sure what you mean by supoptimal paths? It lays out means & incentives quite systematically. I'm curious, if everything is above board what is your theory for preventing price transparency? Also, why does publisher revenue jump up when Google's expectations are disrupted?

Replying to @Iwillleavenow

This one here pains me: you can do an opt out with a single simple button that just opts you out. Why require two options and suggest using a form to fill out?

Thread of 2 tweets

Replying to @Iwillleavenow

Why should those Europeans get all the best dark pattern CMPs?

Replying to @JulesPolonetsky

It's poorly written and open to interpretation, I agree. But I'm not sure what else they would be suggesting? Also, updating DNT to clarify might be relatively straightforward.

Replying to @JulesPolonetsky

The two are quite close though w3.org/TR/tracking-dn…

Replying to @natashanyt and @fatemehx2

GDPR would have a few things to say here, too.

Replying to @tobie

It beauty.

Replying to @WKCosmo

Don't you get a ticket for that?
Yet another brilliant move by @ewarren. amp.theguardian.com/technology/201…

Replying to @laurie_winkless and @ewarren

I know, right? *sigh*
I can't do it but one of you who's eligible should win and invite me 🙂
Quoting a tweet by @ewarren ↗

Replying to @laurie_winkless and @ewarren

Hahaha, why choose!

Replying to @dcreemer

Yay!

Replying to @JulesPolonetsky

Neat! This is going to have a huge effect, having people opt out per site would lead to subpercent results, DNT is already around 10%.

Replying to @katecrawford and @SimonDeDeo

Yes, @msalganik and @RobinCRLee looked into similar issues in comment moderation. Hate speech correlates with discussion of race, and ML just picks up on that.
↺ 1

Replying to @tobie and @torgo, @downey, @w3c, @w3ctag

I'm always available to holler at people from the gallery.

Replying to @gabrielazanfir

Yes, that bit is good, but the user experience they seem to be pointing at for DNS requests is really bad compared to what it can be. It's not clear that you can give users a good opt out experience and comply. I hope they fix that part.

Replying to @euthyphro

Yes.

Replying to @JulesPolonetsky and @dmarti

Of course she is, that's how you win. I'm not sure I agree with Don here, brands are in a prisoner's dilemma with FB. They'd be better off if they all backed out, but then the defector would have a huge incentive to advertise. Same with AMP.

Replying to @derGeistbot and @TJBreed

This broke me.
This is how I twitter.
Quoting a tweet by @PDLComics ↗

Replying to @ceciliakang

I don't think they need the money, but might they need the influence? If they lose political support from those who think monopolies, CDA230, lack of tech accountability, etc. are OK, they might be in for a pretty rough ride.

Replying to @JulesPolonetsky and @dmarti

You can't effect change by losing. If I were running I would use every ugly data trick in the book and then make it illegal. Not in the sense that the ends justify the means, but in this case I would posit that the harm/benefit ratio is worth it.

Replying to @JulesPolonetsky and @dmarti

Some politicians have values 😁 To make a parallel, a non-negligible part of my salary comes from data practices I dislike, I'm still working towards alternatives (and being paid to do so).

Replying to @JulesPolonetsky and @dmarti

With politics, an important driver of reform are changes that affect the playing field but don't impact one side more than the other.

Replying to @null and @Carnage4Life

We can still fix this, Dare. Especially those of us who remember what the plan was.
↺ 1
Not that it’s much consolation but French paper Libération has it as “Esther Duflo and husband”. It might just be a case of nationalism trumping mysogyny.
↺ 2
I return to this every time someone tells me that "the GDPR is a European thing, it wouldn't work with Americans" as if Americans were some kind of pain-relishing morons who just loved having their autonomy abused by unknown data brokers. Much of the GDPR comes from the US. 🇪🇺🇺🇸
Quoting a tweet by @gabrielazanfir ↗
↺ 8
Many are - rightly - advocating for a federal privacy act to avoid state-by-state madness. But digital companies are global companies now, thinking at the federal level is thinking small. What would help business most is a global standard. It's time to port GDPR over to US law.
↺ 2
As @gabrielazanfir shows there, this would just be the return home of a number of American inventions. There's a tendency in the US to think that everything Americans did and loved pre-Reagan is un-American. It's more than time to unlearn that.
↺ 1

Thread of 3 tweets

Replying to @dmarti

You need to talk to @tobie, if you haven't already.

Replying to @recifs

Oui, c’est à ça que je réagissais :)

Replying to @dmarti and @tobie

CoC aren’t enforceable in quite the same way, which makes this a little bit complicated. @tobie has cool ideas around licenses and rights. Maybe we could even move this to a Keybase chat?

Replying to @ceciliakang

When I was last in Sacramento the word was that Newsom had given up on this (pretty terrible) idea, has he flipped or is Yang just behind by six months?
Unpopular opinion: a better word for "software engineer" is "technocrat".
↺ 5

Replying to @aljopainter

Doesn't make it less true!

Replying to @aljopainter

They used to be, back when we were hackers. This has changed much since.

Replying to @aljopainter and @xmlprague

Yes, some of us remain. But it's a minority. Also note that technocrats never want to run the world, they just want to direct how things work "for the greater good."
↺ 1

Replying to @awendt and @Chronotope

See the thread I reference for some details. That's recent, and a relatively small group of companies lacking sophistication on the topic.
Nor, indeed, do we need new jails for anything else.
Quoting a tweet by @s_phia_ ↗
A centralised Do Not Track registry can’t work as it’d need a universal ID, which would just make things worse. There are better ways to achieve the same. Apart from that there are quite a few things to like in @RonWyden’s “Mind Your Own Business Act” — starting with the name!
Quoting a tweet by @realdanstoller ↗
CORRECTION: @RonWyden's "Mind Your Own Business" bill has two DNT mechanisms, one supported by browser/OS setting and the other through a privacy-preserving system to be queried by data brokers. Good stuff!
A centralised Do Not Track registry can’t work as it’d need a universal ID, which would just make things worse. There are better ways to achieve the same. Apart from that there are quite a few things to like in @RonWyden’s “Mind Your Own Business Act” — starting with the name!

Replying to @HerHandsMyHands and @anildash, @SarahTaber_bww

Absolutely, it's a huge guarantee. On top of that, defining what counts as political is near impossible. When they last tried to do that much of what you'd expect from a newspaper became flagged as political.
An excellent article from @matthewstoller along with details in a thread below. "Tech Companies Are Destroying Democracy and the Free Press" — we chose to make it work this way, we can choose a different path. nytimes.com/2019/10/17/opi…
Quoting a tweet by @matthewstoller ↗
↺ 2

Replying to @tomdale

This, yes, this, so fucking this.
Is there specific history behind the fact that American ATMs have such asinine UIs?

Replying to @briankardell

Everywhere: put card, pin, pick amount, receipt?, cash & card back. US: put card in & out, it's chip so put back in, pin, what kind of operation, what type of account, do you want to pay for this, receipt?, get cash, card is locked until you press exit.

Replying to @Chronotope

All of them!

Replying to @chrishuntwalker

Rarely great, but the only place I've seen that is comparably bad is Japan.

Replying to @scshepard

Gotta be compliant!

Replying to @SenorMonkey and @KyleIvins

Those used in the US.

Replying to @azeem and @guardian, @shoshanazuboff, @PaulNemitz

You are probably right that it follows a power law, but teasing it out is hard. The Guardian likely never gets data from most of those and they don't know what is being done. They don't know which are tied to revenue, especially as blocking one could have effects months later.

Replying to @azeem and @guardian, @shoshanazuboff, @PaulNemitz

This is a solvable problem, but it's almost impossible to fix purely from the publisher side. Imposing supply chain transparency is one part, making browsers comply with privacy law another. We'll get there!

Replying to @null and @AmneMachin

I have seen many crazy things on this here site over the years, but someone claiming that endnotes are anything but the evil inconvenient consequence of lazy typesetting by a publisher who hates their readers is a whole new level.

Replying to @jasnell and @taravancil

The W3C doesn't fare much better. Standard groups are often highly tolerant of toxicity. You can pretty much only grow white men in toxic soil.

Replying to @adambroach and @jasnell, @taravancil

I know. I don't think it's something that can be fixed without active policing, which is a major change of tack for these orgs.

Replying to @taravancil

DoH.
This is a really cool position. You risk ending up sitting on the same floor as I do, but other than that it’s really cool.
Quoting a tweet by @PrivacyProject ↗
↺ 2

Replying to @Iwillleavenow

It's a good rabbit hole, though.
This is the most disappointing thing that I have seen happen at The Times since joining. @runasand is an outstanding colleague and amazing to work with.
Quoting a tweet by @runasand ↗
↺ 3
Question for all you fine privacy/legal folks here: do successful California ballot initiatives stand more robustly against federal preemption? (As state laws they are hharder to change.) Put differently, if (when) #CPREA passes, does this constrain potential federal privacy law?
↺ 1

Replying to @thezedwards

Thanks Zach, this is cool.

Replying to @null and @DSepDC, @Chronotope

But my question is: would the higher threshold for ballot initiatives (which are quasi state constitutional in CA) raise the bar for preemption. It seems that yes. CPREA aligns a lot with the GDPR, for any global business that seems like a step in the right direction, no?

Replying to @null and @dansereduick

Opinions seem to differ 😁

Replying to @null and @DSepDC, @Chronotope

What I mean by raising the bar is potentially providing a floor below which federal cannot go, at least in CA. I am not a lawyer nor am I American, but it would make sense if preemption were barred from *decreasing* the rights of Californians.

Replying to @null and @DSepDC, @Chronotope

The purpose of privacy law is to re-enfranchise people with respect to their own data and autonomy, so I am certainly sensitive to the disenfranchisement argument. But Californians shouldn’t be held up by federal slowness, either.

Replying to @null and @DSepDC, @Chronotope

And it would seem unjust that a federal statute could limit their civil rights.

Replying to @null and @dansereduick

I was mostly wondering if federal statutes were somehow prohibited from removing civil rights that states might grant or if there might be a clear path to challenge such a removal. I understand that it’s not an area of strict certainty :)

Replying to @morar

Indeed, it’s not straightforward :)

Replying to @null and @dansereduick

Going against state rights with the goal of *limiting* civil rights atop a background of privacy? What could possibly go wrong?

Replying to @null and @dansereduick

What I find the most promising with CPREA is that it tends to align with GDPR. Digital businesses need a global standard, and alignment to the GDPR makes sense. I hope the federal law will consider that.

Replying to @null and @dansereduick

Much agreed.

Replying to @null and @eyesondesign00

I think he got a season pass 2016-2020.

Replying to @matthewstoller

Matt, @AlecStapp is the guy who argued that G/FB aren’t dominant sources of referral traffic by counting the bytes that various services (eg. video) transmitted. Which is extra funny because a referral click maps to 0 bytes. Let’s just say he’s a very creative thinker :)
↺ 1

Replying to @null and @DSepDC, @Chronotope

Thanks. That makes for an interesting dynamic.

Replying to @null and @DSepDC, @Chronotope

Right. It would then have to prove that it is better, which would be fun.
Mes très chers, savez-vous auprès de qui il faut porter plainte quand on a affaire à @la_cipav et qu'il devient péniblement évident qu'ils consomment des stupéfiants particulièrement intenses?

Thread of 2 tweets

Replying to @Chronotope

I think the word for that is "being old".

Replying to @seanmmcdonald

In an incipient way, yes. They could be taken further in that direction, and indeed some people are thinking about that.

Replying to @jensimmons

Not breaking the web faster than it can adapt.

Replying to @null and @SimonDeDeo

Further wrinkle: being more selective is more work than just liking anyone who looks kinda OK. Does it lead to greater fatigue? To increased commitment when it produces an encounter? Also, does Tinder use selectiveness as a signal so that selective men would be recommended more?

Replying to @tabatkins

So many times...

Replying to @jason_kint and @random_walker

This points to a broader problem we have in making good privacy regulation. It’s very easy to define behaviour at the extremes: only a very strict minimum and you must ask for opt in to even basic trustworthy things (GDPR) or anything goes and users can opt out of the bad (CCPA).
Neither of these is good. I’d want a “reasonable” starting point, with opt out to bare minimum if you want (and possibly opt in to more tracking if you’re into that, why not). There’s plenty you can do in first-party personalisation and analytics that’s respectful of people.
But we have no broad consensus on what “reasonable” is, and the notion of using data in a trustworthy manner has been so thoroughly discredited that it’s hard to even start building towards. It’s still worth a try, though :)

Thread of 3 tweets

Replying to @johnnyryan and @jason_kint, @random_walker

I'd see it that way, but ICO guidance seems to differ 😁

Replying to @johnnyryan and @jason_kint, @random_walker

ICO guidance on cookie consent starts at a very limited level, it is way stricter than I would consider warranted. Basic analytics and crazy RTB end up with the same user experience which makes it hard for good players to differentiate from the bad.

Replying to @johnnyryan and @jason_kint, @random_walker

It's the fateful collision between ePD and GDPR criteria for consent, taken in a rather strict sense. For the milder end they even have some "you shouldn't do that but we might not look too closely nudge-nudge wink-wink" language in there but that's hardly helpful.

Replying to @rigow and @johnnyryan, @jason_kint, @random_walker

It can't be just tech. GDPR is missing a strong first/third-party distinction, anyone can be a controller, and that breaks fast. Multiple controllership should be drastically curtailed. It makes sense for users, helps publishers, targets OBA.

Replying to @rigow and @johnnyryan, @jason_kint, @random_walker

Nope, the CJEU decided otherwise in Fashion ID. But that misses the point: Facebook should not be a controller at all when 3P. Legaltech: I have a few ideas, but are there takers? We fucked up, my friend, we need to clean up our mess.

Replying to @euthyphro

Ooooooh! I'm jealous 😁

Replying to @donohoe and @jason_kint, @richardgingras

The law can have issues, but when you can decrease the quality of your product this radically (for end users) just to make a political point, it really shows you're not worried about competition!
Can someone please get the UK and US to stop holding each other's beer for political inanity? nyti.ms/2Jj4hMk

Replying to @oliviasolon

I once got a Twitter voucher for $100 of self-promotion. I was fully booked so I just picked a political blog post to push. It mostly resulted in a lot of confused people. I hope this doesn't make me some kind thought-leadering imagineer.

Replying to @oliviasolon

I reckon I indeed am a recovering digitalchemist.
"Goliath: The 100-year War Between Monopoly Power and Democracy", by @matthewstoller. A struggle for power of epic proportion with a big cast of larger-than-life characters. It's like Game of Thrones except that more people die and it really happened.
↺ 9
It's somewhat lighter on dragons, but if you have ever wondered why we are in such a bad place economically and socially, this book has some history for you to consider. It doesn't have to be this fucked up.
↺ 2

Thread of 2 tweets

Replying to @MatthewEGunter

Sure, but that doesn't make it any less interesting. And a few things happened that century.
Is there any good scholarship on network effects in the value of data (such that adding a fact to a knowledge graph increases the value of other facts in the graph too)? I'm finding lots of really bad VC musings on "data network effects" but they seem to mostly be confused.

Replying to @deaneckles

That's... a very short reference, Dean 🙂

Replying to @rigow

Media isn’t blocking technology — but technology that doesn’t distinguish between first and third party is not useful. Microsoft was right about that!

Replying to @ElieSl

Et entre les deux un gros dîner fou fou fou?
This is the problem with all of our pretty monopolies: scale corrupts.
Quoting a tweet by @can ↗

Replying to @can

It was a good twete! Now mine is broken 💔

Replying to @Chronotope

You don't need to wait for history, it looks bad right now. Perhaps the most worrying is that @mosseri seems sincere. He didn't reach out to @cwarzel out of a profit motive, he really believes that technology is neutral. At that level of responsibility, that's negligent.
↺ 2
Scale corrupts; Web scale corrupts absolutely.
↺ 9

Replying to @can

*groan*

Replying to @swodinsky

I have long had this theory that Facebook allows you to declare your gender but infers the gender used in targeting from other sources. I was in there as male but I always got campaigns clearly targeted at women (as in tampons, breastfeeding bras, etc.).

Replying to @swodinsky

A device, definitely not. An IP address, some of the time. If you're looking for inference confounders I doubt it's that because they know enough identity (and I blocked the pixel a long time ago). But my social graph could possibly look like I'm a woman.

Replying to @swodinsky

What are you looking for? I'm no expert but I know the folks who work on network science have some good results. I remember for instance that they found some puzzling structure in many networks in terms of friends and professional overlaps. Turns out they could predict spouses.

Replying to @swodinsky

Replying to @swodinsky

An older look at the structure of the social graph: researchgate.net/publication/51…. I haven't been looking at that neck of the woods for a while, but I might be able to dig stuff up if you have specific questions.

Replying to @torgo

Here's to a wonderful next half century!

Replying to @mathewgoldsholl and @superwuster

The easiest thing would be to have some form of online media (possibly created for this purpose) writing the desired message and then push that as paid content. FB know this, last time they "cracked down" on political ads they flagged huge amounts of legit journalistic content.

Replying to @mathewgoldsholl and @superwuster

I don't think that lying online is a problem, I would say the problem is having a platform so large, incentivised to spread what is viral, and with zero external oversight such that bad things happen from its scale alone. I could be wrong but fixing just this seems whack-a-mole.
So my preferred solution would be to break it up, then enforce standards & interoperability between social networks (the standards largely exist) and strong privacy law so it doesn't come back. Then the lies will be at Fox News scale only, which sucks but society can handle.

Thread of 2 tweets

Replying to @cwarzel

We should do the exact same thing, see if they ban us 😁
"The Oxford Handbook of Causation", by H. Beebee, C. Hitchcock, and P. Menzies. I'm usually suspicious of these big handbooks, but this one was cohesive, well-written, and indeed thorough.
↺ 1
Are there still areas of tech that you find exciting? That you feel aren’t being more harmful than good? That exist in a space that hasn’t been killzoned by the FAANG? Tell me what they are!
↺ 3

Replying to @Chronotope and @cwarzel

I mean look at these engagement numbers! I’m pretty sure it’s all organic! We should also buy fake accounts to drive likes so that the content gets promoted more by The Algorithm.
Quoting a tweet by @JuddLegum ↗

Replying to @perigrin

Last I heard from @OUPPhilosophy they were still debating whether you can have one without the other.

Replying to @Iwillleavenow

Agreed, *but* indeed the privacy setup for most options is really bad, and it’s an area pretty effectively killzoned. Fingers crossed for @snips!

Replying to @null and @dansereduick

Yes, there are always niches, that’s a good point (there are some in B2C too).

Replying to @katebevan and @DaphneFlap

That *is* cool indeed. Do you think there’s space for making home hacking easier, including to non-devs, so that people can make their homes smart without having all their behaviour surveilled?

Replying to @null and @KBTechEnt, @Chronotope

*That* is seriously cool. Others have noted that there’s plenty we can build to make life easier and that’s true. It’s just a shame so much of it comes at a steep privacy trade-off — but in this case it looks like not!

Replying to @Iwillleavenow and @snips

It's like predatory lending but for autonomy. I wonder how big a market there is for alternatives, it's a little hard to compete with monopolies.

Replying to @dmarti

Those are neat tools but if you can't build cool successful stuff with them it tampers the interest 😁 Also I've already used almost all of them!

Replying to @drogersuk

Congrats David!

Replying to @johnwilander

A lot of the people I know in gaming seem to talk about how painful it is to monetise in an app store world. Pi: yes, others say the same. I wonder how close to we are to making that world work for everyone without involving a centralised overlord. It would be neat.

Replying to @johnwilander

Your mention of AR makes me curious: have you seen anything cool in that space that doesn’t rely on massive amounts of existing data (eg. a maps system) and lots of (potential) tracking/centralising?

Replying to @lukemulks

I like this one, but I feel like it’s been the Next Big Thing for what, five years now? Is there a risk that it’s one of those things that will always be just around the corner?

Replying to @lukemulks and @brave

That’s cool, I look forward to seeing what you put in @brave. I looked at it while at science.ai (to make the permanent scientific record more permanent) and again a couple of years ago as storage for a social network. It certainly has a lot of nice properties.

Replying to @johnwilander

I think that may be true on the Web, less so in mobile apps, and not in IoT/home. I agree that the privacy battle is headed in the right direction overall, even if it feels quite drawn out and will likely continue to be until sudden collapse.

Replying to @johnwilander

In terms of pessimism I am more worried about monopolies. It’s a harder fight and the remedies are more intricate. (Facebook is probably the easiest.)

Replying to @johnwilander

Part of the reason I was asking the initial question is that is seems clear (to me) that we’re in an innovation trough. But I don’t know how deep the trough goes, or whether I’m missing some important development that’s about to turn the tables.

Replying to @adambroach and @katebevan, @DaphneFlap, @mycroft_ai

There’s a lot of good stuff in there! Privacy is a feature that will certainly help convince people, but it can’t be the only advantage, even at feature-parity — when in doubt people will still trust the big brands more.

Replying to @adambroach

I wonder if there’s a potential coming world in which repairable things are valued more highly, leading to more widespread printers. Sure, plastic and all, but if you can change just one part it’s still a win.

Replying to @adambroach

My concern right now is that while I completely get the attraction of 3D printing, it still feels like something that would attract hobbyists more than regular folks. I’m trying to think what the inflection point could be.

Replying to @null and @josh_braun

I’ll admit I did *not* expect Linux on the desktop to make a showing today! That’s pretty cool — the screenshots indeed look swell. I’ll tuck this away to try it out, thanks!

Replying to @adambroach and @katebevan, @DaphneFlap, @mycroft_ai

I think more than individual advantages it’s the systemic advantage that gets them wins: they have broad, relatively coherent offerings so that they can plug into themselves and offer some form of convenience.

Replying to @adambroach and @katebevan, @DaphneFlap, @mycroft_ai

Conversely, everything that is open is a bunch of disparate small things, just the time you need to invest to *find* other parts of the ecosystem is forbidding. I think the solution here might be a large collusion of small projects. Hard to govern, but the alternative sucks.

Replying to @adambroach

Adam, if you think microwaves are easy to use I’ve got some VCRs to sell you.

Replying to @rlbarnes and @BriarApp, @nycmesh

It does indeed — but no one seems to have figured out the really innovative breakthrough which is to have them spill over into the mainstream.

Replying to @adambroach

Hahaha, that sounds terrifying :) Some microwaves are usable, but they still make completely mystifying ones (even if safely so).

Replying to @null and @josh_braun

Sounds like it might be time for me to finally execute on my replacement for PDF :)

Replying to @null and @josh_braun

Email is impossible to get right, we should just agree on a moratorium on usage and redesign it from scratch.

Replying to @null and @marionpdaly

I want cheap eInk that you can just stick everywhere, but no one else seems to care.

Replying to @null and @josh_braun

There are plenty of OpenRTB channels *begging* to spam you!

Replying to @null and @marionpdaly

A dress would rock. Right now you can’t even find a transparent watch that makes it look like you have the time tattooed on your wrist, so what’s the point really?

Replying to @adambroach and @katebevan, @DaphneFlap, @mycroft_ai

People *do* value their privacy, but the switching costs and cognitive load of alternatives makes it a hacker-only option.

Replying to @null and @josh_braun

Thanks, queueing up in my reading list!

Replying to @rlbarnes and @BriarApp, @nycmesh

I don't disagree! I'm definitely interested in hearing about anything there that's grounded in usage rather than pure tech!

Replying to @fantasai and @r12a

Much agreed!

Replying to @cwarzel

This could make sense if they were planning to expand into more non-fiction, possibly courseware. Most MOOCs are unwatchable at 1x speeds.

Replying to @annbass and @makerfaire

Yes, there’s a lot of promise there.

Replying to @baekdal

In the US, no one would trust utilities not to cheat :)

Replying to @TzviyaSiegman

And brain interfaces to move them!
Data rights, not just privacy, are the new frontline. Should a 3rd party ever be allowed to be a controller? Should 1st parties have transparency into the handling of their constituents? We saw the (unfinished) tussle between publishers and Google over this, here is LADOT v Uber.
Quoting a tweet by @swodinsky ↗
↺ 4
I've said this before, but if you ever wonder what the difference is between having your product designed through data informed by humans instead of humans informed by data the train wreck that is the @netflix experience is a great example.
Quoting a tweet by @ArfMeasures ↗
↺ 19

Replying to @lukemulks and @netflix

So much truth. I feel every conversation with my wife about what to watch is either of us completing half a sentence before jumping out of our skin from that sound.

Replying to @fatemehx2

Assistive: definitely. Self-sovereign: same, though it feels like the offering is still pretty spotty and scattered (but that's something to fix). I worry about identity for the transient. I see the value, but historically has it been used for good?

Replying to @fatemehx2

Same, but it's slooooooow.

Replying to @alexanderdanilo and @brucel

They grow up so fast!

Replying to @Sally_Hubbard

In fairness, DoH is the right thing to do here. DNS tracking is particularly vile and users are very much defenceless. Also the data goes to ISPs, who are hardly stalwart bastions of ethics and procompetitive conduct. Google already pushed them off the cliff with HTTPS Everywhere
The problem is that Google is picking and choosing what they do for privacy and limiting it to what won’t hurt them. Contrary to what @HalSinger purports, they won’t be curtailing third-party cookies. It’s just a move to make it look like they care, the feature is a joke.
↺ 1
It will also be very difficult to observe pricing changes. Google has full control over the auction system and can tweak the prices at will — it’s a complete black box. If they suspect people will be observing prices for anticompetitive behaviour, they can just tip the scales.
In fact, they switched to first-price auctions this year and no one can tell what effect it had on prices ¯\_(ツ)_/¯ So I think DoH is the wrong tree to bark up at. Why they won’t do ITP and supply-chain transparency might be more revealing.

Thread of 4 tweets

Replying to @HalSinger and @Sally_Hubbard

Oh, I don’t in the least disagree with the overall analysis, I just don’t think that DoH is a strong angle from which to make this case. Regarding price: if their auction system were fair, why insist so consistently that it must remain opaque?

Replying to @sroussey and @fatemehx2

Things aren't changing as fast as I'd like them to.

Replying to @sroussey and @fatemehx2

Better regulation, better enforcement, and better privacy preserving options now.

Replying to @triblondon

Egg Mogg.
↺ 1

Replying to @triblondon

Ambulance & Chaser.
↺ 1
10yo is spreading the good word on privacy, can't start too early!

Replying to @null and @marcosc

But they're the same thing, no?
The year is 2138. Every candidate kicks off their campaign with the Pledge of Honesty: "I am doing this to run false ads." No one recalls where this tradition came from and observers often note that it seems backwards, but few would trust a candidate who hadn't uttered the words.

Replying to @lyzidiamond and @msdixon, @glitch

All the cool people kept being annoying about how cool it is. It turns out they were right, too.

Replying to @johnwilander and @dmarti

It looks like there's a bug with the AMP caching for Twitter. Opening outside the app works m

Replying to @Chronotope and @johnwilander, @dmarti

Nothing ever goes wrong with AMP you evil psycho, AMP is what makes the Web fast, why do you hate poor people?

Replying to @dmarti and @Chronotope, @johnwilander, @FirefoxPreview

The PWA doesn’t use AMP, only the app.

Replying to @Chronotope and @dmarti, @johnwilander, @FirefoxPreview

This makes me wonder… does Twitter use Google’s AMP cache? If I were them and doing AMP I’d use my own so I hadn’t thought about this, but Twitter has some solid capacity for stupidity.

Replying to @Chronotope and @dmarti, @johnwilander, @FirefoxPreview

VERY WEIRD.
Interesting detail in this thread: Twitter uses AMP in its apps, but it didn’t build its own AMP cache — instead it’s using Google’s directly. So Twitter is basically sharing its audience data directly with Google. Cool. Definitely no problem there.
Quoting a tweet by @Chronotope ↗
↺ 6

Replying to @Chronotope and @dmarti, @johnwilander, @FirefoxPreview

You make very good points, but note that they could have at least used Cloudflare. I wonder if they’ve made a deal with Google that they can’t use the data collected that way. Publishers would find such a deal… interesting.

Replying to @null and @benharnett

Replying to @Chronotope and @dmarti, @johnwilander, @FirefoxPreview

You could run your own cache without ties to Google, or at least that’s how the story goes.

Replying to @Chronotope and @dmarti, @johnwilander, @FirefoxPreview

It’s not about worrying. If Twitter managed to strike a deal where G is not a data controller over audience data, that has interesting… market dominance implications. If they tried to do that and failed, it also has those implications. If they didn’t try they’re just stupid.

Replying to @incloud

GA has the interesting property that if it is not configured with the advertising features, then Google is a data processor and cannot make independent use of the data. I don’t think that can be externally observed, though.

Replying to @Chronotope and @dmarti, @johnwilander, @FirefoxPreview

Of course, of course — but I’m actually more interested in controllership deals here than in managing to evade Google entirely.

Replying to @JonFerraiolo

What you post yes, not what you read.
I very much support Twitter trying to address this problem head on (and who wouldn’t like the shade @jack throws sideways in there) but it’s going to be very interesting to see how they handle the thorny case of outlets paying to promote their own content.
Quoting a tweet by @jack ↗
↺ 2
It is quite common for online media to buy ads that don't link to a product (eg. subscription) but instead to an actual article. Content can often be better than any marketing messaging: if people come read your articles and love them, they might subscribe (or see more ads).
But now, some of that content might be political. If it's news coverage, it will very often be, not to mention opinion pieces. At what point are those political in a way that would run afoul of Twitter's rules?
If they're from a trusted news source, you might blanket-accept them all. But defining who is a trusted news source is hard (and some large purveyors are hard to distinguish from state media). If you ban all promotion of articles remotely political, that'll harm media.
However if you accept any news source, then every last PAC out there is going to launch its own online media and just promote political articles. I don't have a silver bullet. Not fucking up at Web scale is hard. I'm very curious to see Twitter's detailed policy and roll out.🔚

Thread of 5 tweets

Replying to @can and @oliviasolon

Didn’t take long:
Quoting a tweet by @sarafischer ↗

Replying to @tim_libert

Yes, but GA does not necessarily grant Google rights over the data, depending on configuration. A kickback would definitely be interesting, but even just terms barring Google controllership would be very noteworthy.

Replying to @can and @oliviasolon

The great thing with analysis of America as a non-American is that I can mostly stick to a basic template.

Replying to @tim_libert

Yes, it certainly is a bizarre decision. Given Twitter, it’s entirely possible that they did that in 2006 and then no one built the replacement.
Someone please tell me @ewarren has a metric plan. The US almost switched but Reagan killed it as part of his comprehensive plan to nuke America back to the 18th century.
"With the slightest little effort of my ghostlike charms I have seen grown men give out a shriek! With the wave of my hand and a well-placed moan I have swept the very bravest off their feet. Yet year after year it's the same routine, And I grow so weary of the sound of screams."

Replying to @can

That, plus making them liable for false advertising in the same way that products are.

Replying to @LAM_Barrett and @WolfieChristl, @swodinsky, @Chronotope, @johnnyryan, @profcarroll, @riptari, @arvind

Thanks 🤗 You too do write excellently on this convoluted garbage jungle!

Replying to @can

Replying to @can

More seriously, it's not a trivial problem, but for products you sell there are limits to how far you can stray from the truth. I think we could get there with political advertising, too. Maybe let them promise crazy nonsense because politics, but not lie about facts.
↺ 1

Replying to @LAM_Barrett and @swodinsky, @WolfieChristl, @Chronotope, @johnnyryan, @profcarroll, @riptari, @arvind

Exactly what Lindsey said. Also, you have a bunch of fans at The Times, you should get drunk with us!

Replying to @swodinsky and @LAM_Barrett, @WolfieChristl, @Chronotope, @johnnyryan, @profcarroll, @riptari, @arvind

Yay!

Replying to @swodinsky and @donohoe, @LAM_Barrett, @WolfieChristl, @Chronotope, @johnnyryan, @profcarroll, @riptari, @arvind

Trail mix is making this party come together already.

Replying to @Chronotope and @donohoe, @swodinsky, @LAM_Barrett, @WolfieChristl, @johnnyryan, @profcarroll, @riptari, @arvind

Well, we didn't have parties but that's something we're definitely going to have to fix in a hurry.
This is a good thread. It assumes however that the governed cannot react fast enough. I am not yet convinced that that's true.
Quoting a tweet by @vgr ↗
↺ 1

Replying to @mdennedy and @random_walker

Mozilla has cared about privacy for a long time, but Firefox took its time in being proactive about it.

Replying to @random_walker

In additional to switching costs and network effects, much of the worst of privacy sits with industries that are not dominated by consumer-facing concerns, such as data broking and adtech.

Replying to @Iwillleavenow

Strong impervious women open bags of candy whenever the fuck they want to.

Replying to @rigow and @mdennedy, @random_walker

The great thing with switching JS off is that it's such a tiny number of people that you can trivially track them. "Oh yeah, that's the guy with JS off."